Apple has reportedly placed limits on how many vulnerabilities security researchers can submit to its bug bounty program after a rise in reports tied to AI-generated mistakes. The change follows an uptick in filings that describe supposed security flaws which are said to be fake or unsupported.
Bug bounty programs are designed to reward researchers for finding real weaknesses before they can be exploited. When large numbers of low-quality or hallucinated reports are submitted, security teams can end up spending time reviewing issues that do not actually affect the software.
The reported move suggests Apple is trying to reduce noise in its disclosure process and keep attention on credible findings. For researchers, the tighter submission rules could mean more scrutiny and a stronger focus on evidence-backed reports rather than broad or speculative claims.
The situation also highlights a growing problem across the tech industry as AI tools are used more often in security work. While those systems can help speed up analysis, they can also produce convincing but inaccurate results, creating extra work for companies that rely on bug bounty programs to surface genuine threats.